criticalCVSS 9.9Vulnerability

CVE-2026-49252

### Impact Prototype pollution in deepstream server v <=10.0.4. Potential privilege escalation from any authenticated user with write permission to any record. ### Patches Yes, upgrade to v10.0.5 ### Workarounds Filter out all messages containing the path `__proto__`, `constructor`, `prototype`, **before they reach the server's message pipeline**

Properties

severity
critical
summary
deepstream is vulnerable to prototype pollution
epss_score
0.0047
cvss_score
9.9
ghsa_published
2026-06-26T21:03:59Z
source_url
https://github.com/advisories/GHSA-9v98-6g37-x9g6
ghsa_updated
2026-06-26T21:04:00Z
ghsa_id
GHSA-9v98-6g37-x9g6
cve_id
CVE-2026-49252
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
is_ghsa_only
false
epss_percentile
0.38253

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/@deepstream/server

AFFECTS (1)

[Software]npm/@deepstream/server

HAS_WEAKNESS (1)

[Weakness]Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-49252 (CVSS 9.9) — Ninja Signal Threat Intelligence | Ninja Signal